Endpoint SLA Compliance Evaluation in Managed Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional patch management systems in managed networks are inefficient due to manual scanning processes, limited detection of unknown products, and difficulties in accurately evaluating service level agreement (SLA) compliance in real-time, leading to delayed or incomplete compliance assessments.

Innovation Solution

An automated method for endpoint-level SLA compliance evaluation, where a management device initiates a scan responsive to trigger events, aggregates relevant state data, and implements product modifications to ensure compliance with defined SLA standards, using a system configured with programming code executable on processors to perform these operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual scanning processes are used in conventional patch management systems, then administrators can detect unpatched products on endpoints, but considerable resources are expended and the process is inefficient

Engineering Contradiction:
Improvepatch management efficiencyVSAvoidadministrative resources expended
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The management device automatically initiates scans responsive to trigger events without requiring manual administrator intervention. The system self-manages the patch detection process by monitoring for vulnerabilities and automatically scanning affected endpoints, eliminating the need for administrators to manually initiate and manage scan operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary scanning and assessment actions automatically when trigger events are detected, such as vulnerability disclosures or security threats. This preliminary automated action prepares the system for rapid response by having compliance data ready before administrators need to take manual intervention.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If conventional scans are limited to known products on endpoints, then the scan process is simpler to manage, but unknown products performing similar functions may be missed and introduce vulnerabilities

Engineering Contradiction:
Improveproduct detection capabilityVSAvoidscan system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The management device performs multiple functions within the scanning system: it detects known products by name, identifies unknown products by functional behavior and characteristics, assesses vulnerability status, and manages patch compliance. This multi-functional approach allows a single system to handle both known and unknown products without requiring separate specialized tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses intermediary assessment processes that analyze product characteristics, functionality, and vulnerability patterns to bridge the gap between known product detection and unknown product identification. These intermediary mechanisms evaluate whether products perform similar functions to known vulnerable products, enabling detection of unknown products without requiring exhaustive prior knowledge of every possible product.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If SLA compliance evaluation is performed in conventional systems, then compliance standards can be established, but information is delayed and inaccurate making it difficult to determine which endpoints are non-compliant

Engineering Contradiction:
ImproveSLA compliance assessment accuracyVSAvoidcompliance evaluation delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements continuous feedback loops where compliance data is automatically collected, assessed, and updated in real-time. When trigger events occur or scans are performed, the system immediately evaluates compliance status against SLA standards and provides feedback on which endpoints are non-compliant. This feedback mechanism ensures accurate, timely information is available for rapid response and mitigation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The compliance assessment process operates continuously rather than periodically. The management device maintains ongoing monitoring of endpoint compliance status, continuously evaluating whether products remain patched and compliant with SLA standards. This continuous action ensures that compliance information is always current and accurate, eliminating delays associated with periodic manual assessments.

Inventive Principle:
Principle #20Continuity of useful action

4Productivity

If manual patch management processes are used, then administrators have control over the process, but the scan may be delayed past SLA deadlines and incomplete compliance assessment occurs

Engineering Contradiction:
Improvecompliance assessment speedVSAvoidSLA deadline adherence
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary compliance assessments and identifies non-compliant endpoints automatically before SLA deadlines are approached. By proactively detecting vulnerabilities and assessing compliance status in advance, the system provides sufficient lead time for administrators to implement patches and maintain compliance, preventing delays past critical deadlines.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management device autonomously monitors compliance status, evaluates SLA adherence, and identifies endpoints requiring attention without waiting for manual administrator initiation. This self-service capability ensures that compliance assessments occur continuously and timely, maintaining reliable adherence to SLA deadlines regardless of administrator availability or workload.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11991053B2Endpoint-level SLA evaluation in managed networks
Publication Date: 2024.05.21 IVANTI INC
  • US11991053B2 patent drawing
  • US11991053B2 patent drawing
  • US11991053B2 patent drawing

AI summary

An embodiment includes a method of real-time, endpoint-specific SLA compliance evaluation in a managed network. The method includes receiving SLA definition input that indicates an SLA definition of the managed network. Responsive to detection of a trigger event, the method includes initiating a scan of endpoints including retrieval of endpoint-level state data. The method includes identifying a portion of the retrieved state data relevant to the SLA definition. The method includes aggregating the portions of the retrieved state data. The method includes determining whether the managed network is SLA compliant at an endpoint-level of granularity based on the aggregated portions. Responsive to the managed network being noncompliant, the method includes identifying a subset of endpoints failing to meet the SLA definition and implementing a product modification process to address a metric of the SLA definition and change a product to bring the first endpoint into compliance.